Set up an SFTP server for Exportify: a guide for IT teams
Exportify needs one SFTP account that can write to a single folder: it connects, uploads one file per export, renames it into place and disconnects, and it never lists, reads or deletes anything else. It logs in with an SSH key or a password, and it records the server’s host key fingerprint and refuses to deliver if that key changes.
This article is for the people who look after the server that receives Exportify’s order files. It describes exactly what Exportify does on that server, so the account can be locked down to the minimum it needs.
Exportify is a Shopify app that exports a store’s orders as files. When a merchant asks you to receive those files, this is the whole of what happens on your side.
What Exportify does on your server
Section titled “What Exportify does on your server”For each delivery, Exportify:
- connects to the host and port the merchant entered
- checks that the server presents the same SSH host key as last time
- logs in with an SSH key or a password, as one named account
- uploads one file, under a temporary name, and renames it into place
- disconnects
Exportify never lists the folder, never reads or downloads anything, and
never deletes a file. The one exception is the merchant’s Test
connection button, which uploads a small file named
exportify_test_ followed by a timestamp, then deletes that file if the
account is allowed to. If it is not allowed, the test still passes and the
file stays for you to remove.
The account
Section titled “The account”One account, used only by Exportify:
- SFTP only, with no shell access and no port forwarding
- confined to the folder the files belong in, for example with
ChrootDirectoryin OpenSSH - allowed to create files in that folder, and to rename them
- no read, list or delete permission needed
The chroot trap. With ChrootDirectory, OpenSSH requires the top
folder to be owned by root and not writable by the account. Uploads
therefore have to go into a writable subfolder, and the merchant has to
set Remote path to that subfolder. A Remote path of / produces
permission denied on every delivery.
Rename permission matters because of the temporary name in step 4. If your
system reads every file in the folder regardless of name, either ignore
files ending in .part, or ask the merchant to turn off Upload safely
on the Delivery settings page.
SSH key login
Section titled “SSH key login”Exportify generates its own key pair per template. The merchant sets Login method to SSH key, and the public key appears on their Delivery settings page for you to add to the account’s authorized keys. Exportify keeps the private key encrypted and never displays it, including to its own support team.
Keys are Ed25519 by default. If the server does not accept Ed25519, the merchant can generate an RSA 4096 key from the same page. A regenerated key replaces the old one immediately, so install the new public key before the next delivery is due.
Key login means you can turn off password authentication for the account entirely.
Source IP addresses
Section titled “Source IP addresses”Exportify runs on cloud infrastructure, so it does not connect from a fixed IP address, and the address changes when servers restart or deploy. An address given today would stop working without warning.
Where a policy asks for an allowlist, these all work with Exportify as it is:
- SSH key login, so a guessed password cannot be used at all
- a non-standard port. Exportify connects to whatever port the merchant enters
- rate limiting or blocking repeated failed logins, and blocking by country
- the account restrictions above, so a successful login can only write into one folder
If your policy cannot accommodate that, ask the merchant to contact Exportify support and say so.
The server identity check
Section titled “The server identity check”On its first successful connection Exportify records the SHA256 fingerprint of your server’s SSH host key, along with the key type, and shows it to the merchant. Every later delivery must present the same key, and deliveries stop if it changes.
You can print the same fingerprint on the server:
ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pubAfter a planned rebuild or key rotation, tell the merchant the new fingerprint. Their Delivery settings page shows the old and new keys side by side with a button to trust the new one.
Protocols and ports
Section titled “Protocols and ports”| Protocol | Default port | Notes |
|---|---|---|
| SFTP | 22 | Preferred. Encrypted, and the only one that supports key login |
| FTPS | 21, or 990 for implicit TLS | Encrypted. The certificate must be issued by a public certificate authority and match the host name |
| FTP | 21 | Unencrypted. Supported for servers that offer nothing else |
Exportify gives up on a connection that has not been established within 15 seconds, and on an FTP server that accepts the connection but does not respond within 30 seconds.
File names
Section titled “File names”The file name comes from the merchant’s template and usually carries a
date or an order number, for example
ShopifyOrder_12345.csv. Files are written one per export: a scheduled
export produces one file covering a period, and a per-order export
produces one file for each order, within a minute or two of the order
being placed.
If a file of the same name already exists, Exportify replaces it.
When a delivery fails
Section titled “When a delivery fails”Exportify tells the difference between a problem that may pass and a problem that needs a change:
- Network problems, such as a timeout, a refused connection or a dropped session, are retried automatically over the following half hour.
- Configuration problems, such as a rejected key, a folder that does not exist, or a folder the account cannot write to, are not retried. The merchant sees the reason on their Delivery settings page.
The merchant can always produce the same file by hand from Exportify and send it to you while a problem is being fixed.
Checklist
Section titled “Checklist”- account created, SFTP only, no shell
- confined to one folder, which the account can write to and rename in
- Remote path agreed, and pointing at a writable subfolder if the account is chrooted
- public key installed, if the merchant is using key login
- host key fingerprint shared with the merchant
- firewall allows connections from any address, or the alternatives above are in place
- merchant has run Test connection and seen the test file arrive